
GIAC Security Essentials
Domain 5Objective 3
Malicious Code & Exploit Mitigation GSEC Practice Questions (Page 6)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 26–30
- 26
Which exploit mitigation technique marks memory pages as non-executable to prevent an attacker from running code in data regions such as the stack or heap?
Select an answer first - 27
A company wants to prevent employees from running unauthorized executables on their Windows workstations. They also want to mitigate memory corruption exploits in allowed applications. Which combination of controls is MOST effective?
Select an answer first - 28
A malware analyst is examining a sample that appears to be packed. Static analysis reveals only a small stub that unpacks the actual payload in memory. Which technique is MOST appropriate to analyze the unpacked payload?
Select an answer first - 29
An organization wants to prevent a zero-day exploit that targets a memory corruption vulnerability in a legacy application. The application must continue to run. Which mitigation strategy would be most effective?
Select an answer first - 30
A hospital's IT team discovers that a workstation on the clinical network is infected with a worm that is spreading to other devices. The worm appears to use SMB to propagate. What is the FIRST step in the incident response process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.